pollar.news
text-only edition
← Back to top stories
Digital · · 4 sources

Rhysida leaks 5.8 terabytes of Berlin government data after €2 million ransom refusal

Berlin authorities established a central crisis unit on Saturday after ransomware collective Rhysida published 1.44 million municipal files, including emergency protocols and employee records, on the dark web.

The ransomware collective Rhysida published nearly 5.8 terabytes of stolen government data on the dark web on Friday, 4 September 2026, following Berlin authorities' refusal to pay an extortion demand. The cybercrime group had demanded 30 Bitcoin, an amount valued at approximately €2 million, before setting a deadline for the city administration. The published repository comprises roughly 1.44 million distinct files extracted from state servers during an intrusion detected weeks earlier. Berlin Governing Mayor Kai Wegner defended the municipal government's stance against extortion, stressing that yielding to ransom demands provides no assurance that stolen records will not be redistributed.

Mayor Kai Wegner outlined the administration's position during an interview with Bild.

Who can state that, even if we had paid, these data would not have already been somewhere else for a long time?

— Kai Wegner

Administrative disruption across city departments

The breach occurred on 14 August 2026 and targeted the computer networks of the Berlin city-state, affecting two primary administrative departments. In response to the breach, IT officials severed network connections for several municipal branches for an entire week to halt lateral movement across state infrastructure. The shutdown particularly impacted the Senate departments responsible for housing and environmental affairs, paralyzing standard municipal workflows. As a direct consequence of the network disconnection, citizens were unable to submit housing allowance applications, and regular benefit payments remained blocked for several days. Municipal authorities affirmed that Berlin's state elections scheduled for 20 September 2026 remain fully secure and will go ahead as planned.

Key events in the Berlin administration cyberattack
Aug 14 Hackers breach Berlin city network, leading to a week-long shutdown of housing and environmental systems
Sep 4 Rhysida publishes 5.8 terabytes of stolen files on the dark web after ransom deadline expires
Sep 5 Berlin government forms a central crisis management unit to evaluate leaked data
Sep 20 Scheduled date for Berlin municipal elections

Scope of leaked personnel and security records

A large portion of the compromised data includes sensitive personal records of civil servants, including personnel salary lists, banking coordinates, identity document scans, and records of internal disciplinary proceedings and professional negligence allegations. In addition to administrative employee data, the archive exposes sensitive operational information, such as hazard prevention protocols belonging to the Berlin fire department and documentation concerning structural expansion projects at the Federal Chancellery. The files also contain national security materials, including State Criminal Police Office (LKA) investigative dossiers and emergency intervention blueprints for chemical, biological, radiological, and nuclear threats. Investigative journalist Lars Winkelsdorf noted that the published cache includes defense contractor details and federal contingency communications designed for catastrophic scenarios.

Crisis unit mobilization and past extortion campaigns

Berlin's state government established a centralized crisis management unit on Saturday, 5 September 2026, to oversee the line-by-line verification and forensic evaluation of the exposed files. City officials labeled the cyberattack an extremely serious criminal offense against the state itself and instructed the general public to refrain from circulating unverified materials on social networks. The administration announced that all individuals and corporate entities compromised by the data release will receive direct notification under German and European Union data protection regulations. The incident follows a similar campaign by the Rhysida group against the British Library in autumn 2023, where attackers demanded over €760,000 before dumping roughly 500,000 files of visitor, subscriber, and staff records onto the dark web when that institution also rejected the demand.

Files published on dark web after ransom refusals
files
British Library (2023)500000
Berlin Administration (2026)1440000
Read the full version on pollar.news →

Sources